Slackware 1268 Published by

Slackware 15.0 has released a critical security update for its Samba package to address multiple high severity vulnerabilities. This new version patches dangerous flaws that could allow unauthenticated attackers to execute arbitrary code or bypass authentication mechanisms. Administrators should prioritize installing the upgrade immediately to protect their file sharing and directory services from potential compromise. You can download the updated packages directly from the official Slackware FTP server and apply them using the standard package upgrade command.

samba (SSA:2026-158-01)




samba (SSA:2026-158-01)


samba (SSA:2026-158-01)

New samba packages are available for Slackware 15.0 to fix security issues.

Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
extra/samba-4.22.10-i586-1_slack15.0.txz: Upgraded.
This is a security release in order to address the following defects:
Missing access checks on reparse point operations.
WORM vfs module does not block overwrites.
auto-enrolment GPO installing CA certificate over http without verification.
Denial of service against AD DC WINS server.
Unauthenticated Remote Code Execution in Samba DCE/RPC SAMR server.
Unauthenticated Remote Code Execution in Samba printing subsystem.
For more information, see:
https://www.samba.org/samba/security/CVE-2026-1933.html
https://www.samba.org/samba/security/CVE-2026-2340.html
https://www.samba.org/samba/security/CVE-2026-3012.html
https://www.samba.org/samba/security/CVE-2026-3238.html
https://www.samba.org/samba/security/CVE-2026-4408.html
https://www.samba.org/samba/security/CVE-2026-4480.html
https://www.cve.org/CVERecord?id=CVE-2026-1933
https://www.cve.org/CVERecord?id=CVE-2026-2340
https://www.cve.org/CVERecord?id=CVE-2026-3012
https://www.cve.org/CVERecord?id=CVE-2026-3238
https://www.cve.org/CVERecord?id=CVE-2026-4408
https://www.cve.org/CVERecord?id=CVE-2026-4480
(* Security fix *)
+--------------------------+

Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
( http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/extra/samba-4.22.10-i586-1_slack15.0.txz

Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/extra/samba-4.22.10-x86_64-1_slack15.0.txz

MD5 signatures:
+-------------+

Slackware 15.0 package:
74437119c84e65f40ff2d1074fc71080 samba-4.22.10-i586-1_slack15.0.txz

Slackware x86_64 15.0 package:
55fc2128809e2e0ab6a9fe31014525e7 samba-4.22.10-x86_64-1_slack15.0.txz

Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg samba-4.22.10-i586-1_slack15.0.txz

Then, if Samba is running restart it:

# /etc/rc.d/rc.samba restart

+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key